Legal
Privacy Policy
Effective date: September 6, 2026 · Applies to Regimly v0.8+ · Operated by Svetlana Chrysler (sole proprietor) · Contact: privacy@regimly.com
Regimly (“we”, “us”) is a skincare organization and education app. This policy explains what we process, why, where it lives, and the choices you have. It reflects the app as actually built — every statement below was verified against the application source code and live backend configuration on the effective date.
1. What we process
- Account: email address (email/password accounts) or your Google / Apple identity, and a Firebase Authentication user ID. Guest mode uses an anonymous ID with no email.
- Profile: first name, an age range (14–17 / 18–29 / 30–44 / 45+ — we never collect, store, or transmit your exact age), skin type, and skin concerns.
- Products: the products you add (brand, name, category, optional size and ingredient text) and the product photos you take.
- Ingredient-label photos: read on your device. Uploaded only if you explicitly ask for alternatives to a product.
- Progress photos (your face): stored on your device only. Never uploaded. Removed on sign-out and when a different user signs in on the device.
- Remi chat: kept on your device. Messages are processed transiently by our backend AI at request time and are not stored on our servers.
- Usage & diagnostics: Firebase Analytics usage events — only after you opt in (see §9) — and Crashlytics crash reports (device model, OS version, installation identifiers). We do not collect the Google Advertising ID or Apple IDFA, and there is no advertising in the app.
2. Where your data lives
- Database (profile, shelf, current routine): Google Cloud Firestore, region eur3 (European Union), synced for registered users so a reinstall or new phone restores them. Guests are never synced.
- Photos (products, avatar): Google Cloud Storage, region us-central1 (United States).
- AI processing: Google Cloud Vertex AI, region europe-west4 (European Union).
- On your device only: chat history, check-ins and streaks, progress photos, language preference.
3. AI processing (Google Vertex AI — Gemini)
Product identification, routine generation, Remi’s answers and the alternatives feature run on Google Cloud Vertex AI (Gemini models), always through our backend — the app holds no AI credentials. Depending on the feature, the AI receives: product or ingredient-label photos, your product list, skin type, concerns, age range, and your chat messages, in your chosen language.
What the AI never receives: your name, email, exact age, user ID, or face photos. Per Google Cloud’s Vertex AI terms, customer inputs and outputs are not used to train Google’s models; processing is transient in the EU region we selected. We do not store raw AI requests; results you choose to keep (an identified product, a generated routine) are saved to your profile.
4. Why we process it
- Provide and personalize skincare routines; identify products and ingredients; flag conflicts and overlaps; offer alternatives; operate Remi, the in-app assistant (performance of our contract with you).
- Keep your shelf and routine restorable across devices (contract).
- Measure usage — with your consent only: analytics is off until you opt in, and you can withdraw at any time (see §9).
- Diagnose crashes (legitimate interest in keeping the app stable and secure).
- Security, abuse prevention, and legal compliance.
5. Who receives data
- Google (Firebase & Google Cloud): authentication, database, file storage, serverless functions, analytics, crash reporting, Vertex AI — as our processor.
- Open Beauty Facts (non-profit product database): receives only the product-name text you search. No identity, no photos.
- Nobody else. No data brokers, no ad networks, no sale of personal data. A subscription SDK (RevenueCat) is present in the binary but not activated and receives nothing; this policy will be updated before subscriptions launch.
6. Retention & deletion
- Delete in the app: Profile tab → Delete Account → Delete, then confirm your identity (password or Google) — removes your photos, profile, shelf, routine, and sign-in, immediately and permanently.
- Delete from the web (no app needed): the /delete-account page on this site.
- Deletion is immediate; residual database versions expire within 1 hour; operational logs (which contain no personal content) expire within 30 days. We keep no backups of deleted data.
- Dormant accounts: accounts unused for 6 months are deleted automatically, including all stored data and photos.
- Uninstalling the app removes everything on the device but does not by itself delete your cloud account — use either deletion route above, or the 6-month dormancy deletion will apply.
7. Security
All traffic uses HTTPS/TLS. Cloud data is encrypted at rest. Database and file access is restricted per-user by security rules keyed to your authenticated ID; backend AI calls authenticate with a service account, never an embedded key. Production access is limited to the project owner.
8. International transfers
Your profile, database records and all AI processing stay in the European Union. Product photos are stored in the United States (Google Cloud Storage, us-central1). For EU/EEA users this transfer relies on Google Cloud’s Standard Contractual Clauses and Google LLC’s certification under the EU–U.S. Data Privacy Framework.
9. Analytics & your choices
Analytics is opt-in. The app asks once, on first use, and collects nothing until you agree. You can change your choice at any time in the app: Profile tab → Anonymous usage stats. Advertising ID collection is disabled. Crash reporting runs only in release builds.
10. Age
Regimly is for ages 14 and over. Onboarding requires choosing an age range; choosing “Under 14” ends the session and immediately deletes the just-created account — no profile is stored. Please note the age control is enforced in the app based on the user’s own answer.
11. Your rights
Depending on your law (GDPR, CCPA and others), you may have rights to access, correct, delete, restrict, object, and port your data, and to withdraw consent. Most of these you can exercise directly: everything we hold about you is visible in the app, editable there (Profile tab), and deletable via either deletion route. For anything else: privacy@regimly.com. You may also complain to your local supervisory authority.